Compliance Node Overview
MITRE CAPEC-250 (XML Injection) is an attack pattern in which an attacker uses crafted XML user-controllable input to probe, attack, and inject data into the XML database using techniques similar to SQL injection. Likelihood: High. Maps to CWE-91 (XML Injection / Blind XPath Injection), CWE-74 (Improper Neutralization), CWE-20 (Improper Input Validation), CWE-707. Child patterns: CAPEC-83 XPath Injection, CAPEC-84 XQuery Injection, CAPEC-228 DTD Injection. Compliance: OWASP ASVS V5, OWASP Top 10 A03, NIST SP 800-53 SI-10, PCI DSS Req 6.2.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/250.html
SHA-256 integrity: 2c9eb325bcc5d74593b51d7bbfa2118cef5aef36a0a97a71b257b16fb75d284b
Primary Citations — 8 traced to source
- MITRE CAPEC-250: XML Injection (https://capec.mitre.org/data/definitions/250.html)
- CWE-91: XML Injection (Blind XPath Injection)
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.